GeoSAFE
Geocoding MCP server with GeoPY!
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Geocoding MCP server with GeoPY!
📋 System Requirements
- Python 3.6+
📦 Dependencies
Install all required dependencies:
# Using uv uv sync
Required Packages
- fastmcp: Framework for building Model Context Protocol servers
- geoPy: Python library for accessing and geocoding/reverse geocoding locations.
All dependencies are specified in requirements.txt for easy installation.
📑 Table of Contents
- System Requirements
- Dependencies
- MCP Tools
- Getting Started
- Installation Options
- Claude Desktop
- Elsewhere
- Safety Features
- Development Documentation
- Environment Variables
🛠️ MCP Tools
This MCP server provides the following geocoding tools to Large Language Models (LLMs):
geocode_location
- Takes a user-provided address or place name and returns the best match’s latitude, longitude, and formatted address.
- Handles errors gracefully and returns None if the location is not found or if an error occurs.
reverse_geocode
- Takes a latitude and longitude and returns the nearest address.
- Useful for finding descriptive information about a point on the map.
geocodewithdetails
- Similar to geocode_location but returns additional data such as bounding boxes and more detailed address info, if supported by the geocoder.
geocodemultiplelocations
- Accepts a list of address strings and returns a list of geocoding results (lat/lon/address) for each address.
- Rate-limited to avoid hitting geocoding service quotas.
reversegeocodemultiple_locations
- Accepts a lis
3a0c6d5380b4OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add MCP-geo --env ARC_PASSWORD=${ARC_PASSWORD} --env BING_API_KEY=${BING_API_KEY} -- uvx MCP-geo{
"mcpServers": {
"MCP-geo": {
"command": "uvx",
"args": [
"MCP-geo"
],
"env": {
"ARC_PASSWORD": "${ARC_PASSWORD}",
"BING_API_KEY": "${BING_API_KEY}"
}
}
}
}Exposed tools (7)
7 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
distance_between_addresses | read | |
distance_between_coords | read | |
geocode_location | read | |
geocode_multiple_locations | read | |
geocode_with_details | read | |
reverse_geocode | read | |
reverse_geocode_multiple_locations | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
3a0c6d5380b4full audit observations/trust-audit/mcp-server/webcoderz__geo.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 3a0c6d5380b4 | SAFE | B | 89 | first audit |
Questions
What is the Geo MCP server?
Geocoding MCP server with GeoPY!
What tools does Geo expose?
7 in total: 7 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Geo safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Geo need?
It reads ARC_PASSWORD and BING_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (3a0c6d5380b4), read on 2026-10-08. The repository is watched and re-audited when it changes.